Google pauses bug bounties as cyber threats escalate across sectors
Google has temporarily paused its Open Source Software Vulnerability Rewards Program due to an influx of automated and invalid bug reports. The program, which covers Google-maintained projects like Go, Angular, and Fuchsia, as well as critical third-party dependencies, will resume in the first quarter of next year. Supply chain reports and reports submitted before October 1st are not affected. Google encourages submitters to provide fixes through Patch Rewards or report qualifying Google Cloud issues through Cloud VRP.
Researchers at Proofpoint have uncovered a new tactic by China-aligned hackers impersonating US officials to target AI experts. The group TA419 posed as former White House science official Lynne Edwards Parker and economist Heidi Crebo-Rediker to steal cloud credentials from AI policy experts. The attackers used fake OneDrive pages to capture authenticated sessions, even bypassing multifactor authentication. Researchers recommend verifying unexpected outreach through another channel and using passkeys.
Ukraine’s largest grocery chain, ATB, confirmed a cyberattack after hackers posted a $400,000 extortion demand on its website. The group DataSuckers claimed to have stolen records for 7.9 million customers and more than 11 million orders, including contact details and password hashes, along with employees’ passport information. ATB denied that customer data was compromised and temporarily took some online services offline. The attackers later posted alleged samples and said they would sell the database.
The Pentagon has stopped using Anthropic's AI products, months after designating the company a national security supply chain risk. Sources tell the BBC that Claude was still being used as recently as last week for research, intelligence analysis, and military operations against Iran. The dispute began when Anthropic refused to remove safeguards over concerns about mass surveillance and autonomous weapons. Anthropic is challenging the designation in court.
Meta engineers discovered serious security flaws in its Muse AI agent shortly before launch, according to internal documents. At least one flaw could have allowed a user to escape the virtual machine running their agent and reach sensitive internal Meta databases. Teams worked around the clock on a security push starting August 27th, just 11 days before launch. Meta says it has strengthened Muse through internal testing, red teaming, and its bug bounty program.
Microsoft released emergency updates for an Exchange Server authorization flaw that lets an authenticated attacker read other users’ email and attachments within the same organization. Microsoft has already applied a service-side fix to Exchange Online, so those customers don’t need to act. On-premises administrators should update Exchange Server Subscription Edition RTM, Exchange 2016 CU23, and Exchange 2019 CU14 or CU15. There’s no evidence of exploitation in the wild, but Microsoft says exploitation is more likely.
The FBI confirmed multiple arrests in an investigation into a September cyber incident allegedly involving ShinyHunters. The bureau declined to identify those arrested or comment on the Reuters report that Saif al-Din Khader, known online as Rey, was detained in Jordan and is cooperating with investigators. Dutch police also arrested a 24-year-old alleged ShinyHunters leader last month.
Citrix has identified another actively exploited NetScaler flaw that can crash appliances and keep services unavailable if triggered repeatedly. It affects some customer-managed deployments using SAML authentication and is separate from the two NetScaler vulnerabilities disclosed last week. Citrix has released updates and temporary mitigations, and says it hasn’t identified an impact on the integrity of customer data. CISA ordered US federal agencies to patch by Wednesday and conduct forensic triage.